CVE
- Id
- 4247
- CVE No.
- CVE-2001-1444
- Status
- Candidate
- Description
- The Kerberos Telnet protocol, as implemented by KTH Kerberos IV and Kerberos V (Heimdal), does not encrypt authentication and encryption options sent from the server, which allows remote attackers to downgrade authentication and encryption mechanisms via a man-in-the-middle attack.
- Phase
- Assigned (20050421)
- Votes
- None (candidate not yet proposed)
- Comments